Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Operation Endgame wave 1 ID: td_2024_endgame_w1 May 27, 2024 Multi threat campaign French Gendarmerie, BKA, and Dutch National Police International Completed
Operation Cronos wave 1 ID: td_2024_cronos_w1 Feb 19, 2024 Ransomware NCA and FBI International Completed
Operation Ladybird ID: td_2021_emotet Jan 26, 2021 Malware and botnets Dutch National Police and BKA International Completed
Avalanche network takedown ID: td_2016_avalanche Nov 30, 2016 Criminal hosting and proxies Verden Public Prosecutor International Completed
Operation Tovar ID: td_2014_gameover_zeus May 30, 2014 Malware and botnets FBI and NCA International Completed

Showing 1 to 5 of 5 takedowns

5 results

May 2024

Operation Endgame

IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, Trickbot Multi threat campaign

Lead
French Gendarmerie, BKA, and Dutch National Police
Result
More than 100 servers disrupted or taken down; more than 2,000 domains brought under law-enforcement control; 16 location searches.
Accountability
8 charged, 4 apprehended, and 8 publicly wanted
Return status
Not established in the public record

February 2024

Operation Cronos

LockBit Ransomware

Lead
NCA and FBI
Result
34 servers seized across eight countries; source code and affiliate data obtained; more than 1,000 decryption keys recovered; more than 200 cryptocurrency wallets frozen; approximately 14,000 rogue accounts closed; leak site taken over and operated by law enforcement.
Accountability
4 charged, 3 apprehended, 2 convicted, and 3 publicly wanted
Return status
Returned under the same operators

January 2021

Operation Ladybird

Emotet Malware and botnets

Lead
Dutch National Police and BKA
Result
Roughly 700 command-and-control servers taken over; infected machines redirected to law-enforcement infrastructure; a court-authorized uninstall module was delivered and triggered on 2021-04-25.
Accountability
2 apprehended
Return status
Returned on replacement infrastructure

November 2016

Avalanche network takedown

Avalanche Criminal hosting and proxies

Lead
Verden Public Prosecutor
Result
More than 800,000 domains seized, sinkholed, or blocked; 39 servers seized; 37 premises searched.
Accountability
5 apprehended
Return status
Later activity recorded, link to the original not established

May 2014

Operation Tovar

Gameover Zeus botnet and CryptoLocker ransomware Malware and botnets

Lead
FBI and NCA
Result
Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.
Accountability
1 charged and 1 publicly wanted
Return status
Returned on replacement infrastructure

Previous Page 1 of 1 Next

Filters

Filter takedowns